The count came from the malware's own address book. Early in April 2012 analysts at Doctor Web, a Russian anti-virus company, worked out the routine a trojan called BackDoor.Flashback.39 used to generate names for its control servers, registered several of those names themselves, and listened to the infected machines that called in. On 4 April the company said the botnet held more than 550,000 infected Macs, 56.6 per cent of them in the United States and 19.8 per cent in Canada. The next day one of its analysts, Ivan Sorokin, wrote on Twitter that the figure had passed 600,000, and that 274 of the machines were in Cupertino, the town where Apple has its headquarters.

Kaspersky Lab registered another of the domains on 6 April and counted more than 600,000 unique bots in under a day, over 98 per cent of them Macs by its heuristic reckoning. The route in mattered more. Flashback first appeared in September 2011 as a counterfeit Flash Player installer that a user had to run. By February 2012, Doctor Web said, it was arriving through Java flaws, and from 16 March through CVE-2012-0507, loaded by a script planted on compromised websites; visiting the page was enough. Oracle had fixed that flaw in February. But Apple, not Oracle, still shipped the Java that ran on Macs, and its fix came on 3 April, by which time, as Brian Krebs noted, the flaw was already in the exploit kits aimed at Windows users.

Until Apple had a tool, checking a Mac meant opening Terminal and typing, exactly as written, the commands F-Secure had published. On 10 April Apple said it was developing software to detect and remove Flashback, and was "working with ISPs worldwide to disable this command and control network". Doctor Web said the same day that Apple had tried to have one of its research servers taken down as "involved in a malicious scheme"; its chief executive, Boris Sharov, said the firm had no established security contact at Apple. On 12 April Apple shipped Java updates that removed the most common variants and switched Java off in the browser — on Lion, off again after thirty-five days unused — with a separate removal tool for Lion machines that had no Java.

Then the counts parted. Symantec said its sinkhole showed about 270,000 infected Macs on 11 April and roughly 140,000 by 16 April; Kaspersky reported a fall too. Doctor Web said on 20 April that it still saw some 550,000 a day, and blamed a server run by an unidentified third party that held connections open, stalling bots before they reached anyone else's counter. At the start of May Symantec estimated that an ad-clicking component, hijacking Google searches, could be earning the operators up to $10,000 a day; by mid-May it put the takings at $14,000 in three weeks, from about 10,000 machines that carried it. In June researchers at Sophos noticed that Apple's website no longer said a Mac "doesn't get PC viruses". It said: "It's built to be safe."

Also that month · 2–9 April

Three counts from one server

The server was new, and had gone online without the security it should have had. It held Medicaid and children's health-insurance claims. Intruders reached it on 30 March 2012 and began removing data on 1 April; the breach was detected, and the machine shut down, on 2 April. The Utah Department of Health's first figure was about 24,000 claims. By 6 April it was 181,604 recipients, 25,096 with Social Security numbers; on 9 April it was about 780,000 people — some 280,000 Social Security numbers, and 500,000 people's names, birth dates and addresses — because the server also held eligibility inquiries sent in by healthcare providers. The department blamed a configuration error at the authentication level; a technician had set a weaker password than needed. Officials traced the intruders to Eastern Europe, which the FBI declined to confirm. On 15 May Governor Gary Herbert announced the departure of the state's technology chief, Stephen Fletcher: "As a state government, we failed to honor that commitment." In September 2013 the state said no identity theft had been linked to the breach; the security work since had cost about $9 million.

Also that month · 22–26 April

An oil terminal offline, a bill through the House

Late on Sunday 22 April 2012 malware reached computers at Iran's oil ministry and the National Iranian Oil Company; the ministry said it had tried to delete data on its servers. A virus was detected at Kharg Island, the main crude export terminal, and the ministry, the company and several oil facilities were cut off from the internet as a precaution. The spokesman, Alireza Nikzad, said the main data was undamaged because the general servers were separate from the main ones, and that only some users' data had been compromised; exports, officials said, went on. The International Telecommunication Union asked Kaspersky Lab to investigate. It never recovered a sample, only traces on disk images, and concluded in August that this wiper was real and was not Flame, which the search found instead (May 2012). On 26 April the House passed CISPA, 248 to 168, to let companies and intelligence agencies share threat information. The White House had said the day before that the bill treated domestic cybersecurity as an intelligence activity, and that the President's senior advisers would recommend a veto. It never passed the Senate.

India desk · April 2012

A cartoon for the residents' list

The email went out on 23 March 2012 from a housing co-operative in the south of Kolkata to its residents. It carried a cartoon strip after Satyajit Ray's Sonar Kella, in which the chief minister, Mamata Banerjee, tells Mukul Roy, newly made railway minister, that his predecessor, Dinesh Trivedi, has "vanished". On the night of 12 April the resident who had forwarded it, a chemistry professor at Jadavpur University, was surrounded inside the complex and beaten by ten or twelve men he later told the courts were supporters of the ruling party. Police from the Purba Jadavpur station arrested him and a neighbour, a retired state-government engineer in his seventies, on a Trinamool Congress supporter's complaint under sections 114, 500 and 509 of the Penal Code and section 66A(b) of the Information Technology Act. A magistrate at Alipore bailed both the next day.

On 13 August the West Bengal Human Rights Commission found the arrests unlawful and recommended fifty thousand rupees for each man and proceedings against two officers; the state declined in May 2013. On 10 March 2015 Justice Dipankar Datta of the Calcutta High Court called them "reckless arrests" and ordered the state to pay. A fortnight later the Supreme Court struck section 66A down (March 2015), and the case outlived it: the charge sheet had kept only the 66A counts, yet in September 2021 a magistrate dropped those without closing the file, pending a plea to add two Penal Code sections back. The neighbour died in 2019. A sessions judge at Alipore discharged the professor in January 2023. The section's later arrests are in October and November, and the advisory that followed them in January 2013.

AI Tech desk · April 2012

A machine-learning class becomes a company

On 18 April 2012 two Stanford computer scientists, Daphne Koller and Andrew Ng, launched Coursera with $16 million from Kleiner Perkins Caufield & Byers and New Enterprise Associates, and with Princeton and the universities of Michigan and Pennsylvania joining Stanford to offer free courses, 39 on the first list, humanities among them. It grew out of Ng's online machine-learning course of the previous autumn, for which more than 100,000 people had registered. Online education, Koller said, was "not a fringe phenomenon". Eight days earlier DARPA had announced its Robotics Challenge, citing the Fukushima Daiichi disaster: a $2 million prize for a robot that could drive a utility vehicle, cross rubble, climb a ladder, break through a concrete panel and shut a valve by a leaking pipe, using equipment built for people, with the first phase due to begin in October. A South Korean team, KAIST, took the prize in June 2015. Coursera floated on the New York Stock Exchange in March 2021 and in May 2026 completed its combination with Udemy, with Ng still its chairman.

Digital Guard desk · April 2012

Anti-virus makers buy into the phone

On 2 April 2012 Symantec completed a $28 million purchase of Nukona, whose software fenced off company applications and data on employees' own phones. The next day Sophos agreed to buy DIALOGS of Dortmund, whose smartMan device-management software already ran inside Sophos Mobile Control, for an undisclosed sum. The malware was moving the same way. On 12 April Sophos described a counterfeit Angry Birds Space, offered on unofficial Android markets, that used the GingerBreak exploit to take root control and enlist the phone in a botnet; within a week Trend Micro and Sophos were reporting fake Instagram pages aimed at Russian users, serving an app that ran up charges by texting premium-rate numbers. From November, Android 4.2 asked users before an app could text a premium short code. Microsoft's Security Intelligence Report of 25 April found business networks' leading threat an old one: Conficker, without a new variant since 2009, still spreading mostly through weak or stolen passwords; Check Point ranked it the world's most prevalent malware as late as December 2016.

⏳ Time capsule — April 2012

  • On 1 April Aung San Suu Kyi won the seat of Kawhmu in Myanmar's by-elections with 85 per cent of the vote; her National League for Democracy took 43 of the 44 seats it contested.
  • On 9 April Facebook agreed to buy Instagram for $1 billion in cash and stock; when the deal closed on 6 September, it was paid as $300 million in cash and 23 million shares.
  • Early on 15 April, a hundred years after the Titanic sank with the loss of more than 1,500 lives, passengers and crew of the memorial cruise ship MS Balmoral, which had sailed from Southampton with 1,309 passengers, held a service at the spot in the North Atlantic; after a moment of silence three wreaths were cast onto the water as the ship's whistle sounded.
  • On 19 April India test-fired the Agni-V missile for the first time, from Wheeler Island off the Odisha coast at 8.05 in the morning; its range was put at more than 5,000 kilometres.
Where it stands today — 2026

After the exception

Flashback did not open the Mac to malware; it ended the belief that the Mac was exempt. On 16 October 2012 an Apple update uninstalled Apple's own Java plug-in from every browser, sending anyone who still needed applets to Oracle. In January 2013 Apple switched Java off remotely on machines it did not own, and a month later said employees' Macs had been infected through a Java flaw (February 2013). Intego's sinkholes were still counting about 22,000 infected Macs in January 2014. The first working Mac ransomware arrived inside a signed installer in March 2016; Silver Sparrow reached nearly thirty thousand Macs in February 2021. In 2026 the Mac is defended as a target, not as an exception.

Utah's lesson was retention: the eligibility records on that server, it was reported in May, should have been deleted the day after each inquiry, and had sat there for more than three months. Larger health breaches followed, at Anthem in February 2015 and Change Healthcare in February 2024. The wiper in Iran's oil ministry was followed by one at Saudi Aramco in August. CISPA passed the House again on 18 April 2013, 288 to 127, and stalled again; a similar bill, the Cybersecurity Information Sharing Act, passed the Senate in October 2015 and became law inside a spending bill that December. In Kolkata a case begun under a section struck down in 2015 kept a chemistry professor in court until 2023, and the state, reports said then, had never paid him.